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Abstract 

We define the problem "identity check" : Given a classical description of a quantum 
circuit, determine whether it is almost equivalent to the identity. Explicitly, the task 
is to decide whether the corresponding unitary is close to a complex multiple of the 
identity matrix with respect to the operator norm. We show that this problem is 
^ ! QMA-complete. 

| A generalization of this problem is "equivalence check" : Given two descriptions of 

quantum circuits and a description of a common invariant subspace, decide whether the 
restrictions of the circuits to this subspace almost coincide. We show that equivalence 
' check is also in QMA and hence QMA-complete. 

1 Stating the problem "equivalence check" 

So far there is only one QMA-complete problem known, namely the 3-local Hamiltonian 
problem PQ 121 El ■ Here we give another example that occurs naturally in the problem 
^ . of constructing quantum networks from elementary gates: 

Let U be a quantum network acting on n qubits that consists of two-qubit gates 

U = U k --- U 2 U! . 

Someone claims that the same transformation U could also be implemented by another 
sequence 

V r --V 2 V 1 . 

Assume that he did not tell us why he thinks that this sequence also implements U. How 
difficult is it to determine whether it really does? Also the following slight modification 
of the problem is natural. Usually we are not interested in the whole physical state 
space but rather in a computational subspace. This subspace may, for instance, be 
defined by a quantum error correcting code 0] or a decoherence free subspace [31 |H] • 
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Then it is not relevant whether the alternative network coincides with the original one 
on the whole space but only on the code space. Assume that we already know (for 
example by construction) that the alternative network leaves the subspace invariant. 
Does the alternative circuit agree with the original one when it is restricted to the 
subspace? This is obviously equivalent to the question whether the restriction of 

vM ■ ■ ■ tfu k ■ ■ ■ u 2 u l 

is the identity. 

First we introduce some notations that will be used trough the paper. We denote 
the Hilbert space of a qubit by B := C 2 . Let x E {0, 1}* be an arbitrary binary string. 
We denote the length of x by For any Hilbert space 7i we denote the set of density 
matrices acting on 7i by S(7i). 

We define formally: 

Definition 1 (Equivalence Check) 

Letx,y be classical descriptions of quantum networks consisting ofpoly(\x\) and poly (\y\) 
many two- qubit gates, respectively. Let U x and U y be the unitary transformations im- 
plemented by the circuits acting on n qubits with n = poly(\x\) and n = poly{\y\). 
Given a common invariant subspace V of B® n . Let V be specified by a quantum circuit 

V on ,g®( n + m ) with polynomial complexity such that VV = W\ where W\ is the space 
of all states of £?®( n + m ) where the last qubit is in the state |1). 

The problem equivalence check is to decide whether the restrictions of U x and U y to 

V coincide approximatively. Explicitly we assume that it is promised that either 

1. There is a vector |f) 6 V such that 

||(Z7,E/}-e*l)|¥)||>« 

for all (f) E [0, 2ir) or 

2. There exists an angle <p G [0, 2tt) such that for all vectors |f ) G V 

[|(^-e^l)|*)||< M) 

where 5 — (j,> l/poly(\x\) and 5 — [x > l/poly(\y\). 

In the following section we will show that equivalence check is in QMA. In Sectional 
we will show that a specific instance of equivalence check, namely to decide whether 
a circuit is almost equivalent to the identity, encompasses QMA. Hence equivalence 
check and identity check are both QMA-complete. 

2 Equivalence check is in QMA 

The complexity class QMA consists of the problems of deciding whether a given string 
is in a certain language in QMA. The set of QMA languages is defined following |2j. 
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Definition 2 (QMA) 

Fix e = e(\x\) such that 2 ^Cl^l) < e < 1/3. Then a language L is in QMA if for every 
classical input x £ {0, 1}* one can efficiently generate (by classical precomputation) a 
quantum circuit U x ("verifier") consisting of at most p(\x\) elementary gates for an 
appropriate polynomial p such that U x acts on the Hilbert space 

H ■= B® n * ® B® m * , 

where n x and m x grow at most polynomially in \x\. The first part is the input register 
and the second is the ancilla register. Furthermore U x has the property that 

1. If x G L there exists a quantum state p that is accepted by the circuit with high 
probability, i.e., 

3p£S(B n *), tr(U x (p®\0...0)(0...0\)U x P 1 ) > 1-e, 

where P± is the projection corresponding to the measurement "Is the first qubit in 
state 1 ?". 

2. If x L all quantum states are rejected with high probability, i.e., 

Vp G S(B n *) , tr(U x {p ® |0 . . . 0}(0 . . . 0|) Ul P x ) < e. 

Note that our "witnesses" are mixed states in contrast to the definitions in |2j. 
Due to linearity arguments this modification does not change the language L. Note 
furthermore that it is always possible to construct a verifier for the same language with 
e' arbitrarily close to 0. This "amplification of probabilities" is described in 1] in full 
detail. This may be necessary in Section |3J 

To prove that equivalence check is in QMA we have to describe how to give a witness 
state that proves that U x and U y do not coincide. For an arbitrary unitary operator W 
the difference from multiples of the identity is a normal operator. Hence its operator 
norm is given by the greatest modulus of the eigenvalues. Therefore the operator 
norm distance between W and the set of trivial transformations (global phases) can be 
determined as follows. 

Whenever there exist eigenvalues exp(ia) and exp(i/3) of W the norm distance to 
exp(ii^>)l is at least 

max{|e ia - e%\e if5 -e**|} (1) 

If \a — /3| < 7r the minimum of expression Q is achieved for (ft := (a — (3)/2 and the 
norm distance to the trivial transformations implementing global phases is hence at 

least 

|1 _ e i(«-«/2| = A /2(l-cos((a-/?)/2)). 

Let U x , Uy be the restrictions of U x and U y to V. If case 1 of Definition ^ is true there 
exists eigenvectors \ip a ) and |?/>&) of U^(U y y with eigenvalues e lot and e J/3 , respectively 
such that 

5 < v/2(l - cos((a - (5)/2)) 

In order to check that the eigenvalues corresponding to the given eigenvectors satisfy 
this criterion one can use the phase estimation procedure [7]. 
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Due to the promise that in case 2 one has \/2(l — cos((a — (i)/2) < fx the accuracy 
of the phase estimation has to be chosen such that cos ((a — /?)/2) can be determined 
up to an error of (5 2 — ^ 2 )/4. It remains to check whether \tp a ) and \tpb) are elements 
of V. This can be done using the given circuit V. 

Actually the setting of QMA problems (see Definition [2J requires that the witness 
is one quantum state instead of two. Formulated as an Arthur-Merlin game Merlin 
proves Arthur that a string x is in QMA by sending the witness quantum state. Here he 
may prove that U x Uy has eigenvalues of non- negligible distance by sending the state 
IV'a) <8) \ipb)- A priori it is not clear that Merlin cannot cheat by sending entangled 
(wrong) witnesses. However, one can check easily that the circuit in Fig.l treats any 
state 

5>iv*>®iW> 

3 

as an incoherent mixture of product states \ipa) <S> \ip 3 b ) with weights \cj\ 2 . Note that 
it is also irrelevant whether the witness states \ip a ) and \ipb) are really eigenstates of 
U x Uy. The phase estimation procedure can only produce output that really exists 
as eigenvalues (up to the accuracy that is determined by the size of the used ancilla 
register). In Fig. 1 one can see the whole circuit. 

3 "Identity check" is QMA-complete 

First we state the problem "Identity check" formally. 
Definition 3 (Identity Check) 

Let x be a classical description of a quantum circuit U x of complexity polynomial in 
\x\. Decide whether U x is close to the trivial transformation in the following sense. 
Decide which of the two following cases is true given the promise that either of 1. or 
2. is satisfied: 

1. for all (j) G [0,2vr) 

-e^l|| > <5 

or 

2. there exists an angle (j) G [0, 2ir) such that 

||£4-e^l|| < fi. 

Assume furthermore that 5 — fi > l/poly(\x\). 

Note that this problem is a specific instance of equivalence check. 

The general QMA setting is that a quantum circuit U is given and the problem is 
to decide whether there is a state \ip) such that the state 

U\rp) ® |0...0) 

has the property that the first qubit is with high probability in the state |1). In order to 
show that Identity Check encompasses QMA we construct a circuit Z that implements 
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Figure 1: Circuit used to verify that U x Uy is not close to the identity on the subspace V. The two 
copies of V check that the witness states are really elements of V. The results of this check are 
copied to additional ancilla qubits by Controlled-NOT gates. The main part of the circuit (A k and 
F) is a usual phase estimation procedure. The ancilla registers are initialized into the superposition 
state (1/y/m) Ylk<m W) an< ^ control the implementation of A k := (U x Ul) k . The state \k) obtains 
a phase according to the eigenvalues of A k . By Fourier transformations F the phases can be read 
out from the ancilla registers. A circuit D computes the phase difference and C checks whether 
the difference is sufficiently large and the witness states are elements of the subspace V. 
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Figure 2: Circuit Z consisting of U, W and two controlled phase shifts V and W with phase ip. If 
U rejects all states with high probability the circuit is closer to the identity than in the case that 
there is a state that is likely to be accepted. The first ancilla can only obtain a phase shift 2ip if 
the other ancilla register has been correctly initialized and the input has been accepted by U . 



a unitary close to the identity whenever there is no state that is accepted by U and a 
circuit less close to the identity if there is a witness. The register is extended by one 
qubit and the whole circuit is the transformation 

Z := U ] WUV . 

The transformation V is a phase shift controlled by the states of the ancillas. Whenever 
the ancilla part of the register is initialized in the state 1 ... 0) the additional qubit 
gets a phase exp(i<p). The gate W is a phase shift controlled by the output qubit of 
U. The additional qubit gets a phase exp(i(p) whenever the circuit has accepted (see 
Fig.2). 

Theorem 1 Let U be a quantum circuit on B^( n + m ) with the promise that either of two 
cases in Definition^ is true. Then for the circuit Z in Fig. 2 the following statements 
hold: 

If case 1 is true then we have 

\\Z - e i7 l|| > v/2(l - cos <p) - 2^e 

for all 7 G R. 

If case 2 is true then we have 

\\Z - e lLp,2 l\\ < 2y/l - cos(y>/2) + 2^21 

Proof: The effect of Z on a general state |^) can be understood if we express \^f) 

as 

|#) = 1^)0 |* 2 ), 
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where is a state with ancillas all set to and \^ 2 ) a state with ancilla register in 
states different from 1 . . . 0) . We have 

Z|¥) = U*WUV\Wi) rfWUV\$2) . 

Consider case 2 and the effect of Z on the summand |^i): 

rfWUVlVx) = U^WPxUV\^x) U ] W{1 - P x )UV\$x) 

where Pi is (see Definition^ the projection onto the state 1 1) of the output qubit. By 
definition of W one has 

W(l - Pi) = (1 - Pi) . 

Hence we have 

Z|*i) = U ] W PiUV\^i)@U ] {l-P^UV^i) = tfWP 1 UV\$ 1 )+V\$x)-tfP 1 UV\$x) 

Since the probability of acceptance is at most e the length of the vector P\UV\^i) is 
at most yfe\\ |^i)||. We conclude 

\\Z\V X ) -V\*x)\\ <2Vi|||*i)||. 

Note that \\V — exp(iy>/2)l|| = |1 — exp(i^/2)|| due to the arguments at the end of 
Section |2 Due to \\V\%i) - e^/ 2 |*i)|| < |1 - exp(i<p/2)| || |^i)|| we have 

- e^ 2 |M/i)|| < (2Vi + |l- exp(^/2)|) || |*!)|| . (2) 

Consider the effect of Z on l^)- 

\\Z\V 2 ) ~ e llp/2 \V 2 ) || = WUV\V 2 ) - e iv/2 \^ 2 ) \\ 

= \\U\W - e i ^ 2 l)U\^ 2 )\\ < \\W - e^lH |||* 2 )|| . 

Together with inequality we have 

||Z|*)-e^ 2 |*>|| < (|l-exp( l >/2)|+2 > /i)(|||*i>||+|t3)||) < >/2(|l-eJcp(i^/2)|+2 > /i) . 
With |1 — exp(i<p/2)\ = y/2(l — cos Lp/2) we have 

\\Z- e itp/2 l\\ < 2 v / T^cos(^72y + 2\ / 27. 

Consider case 1. Let \tp) be a state that is accepted by U with probability 1 — e. 
Define Pq := 1 — Pi. We take the state vector 

I*) :=-=(|0) + |l))®|^)®|0...0). 
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We have 

Z|tf) = rfWUV-=(\0) + \l))®\i/>)®\0...0) 
V2 

= tfWU-={\0) +e i<p \l))® |V)®|0... 0) 
v2 

= U*W(1 - P )U-^=(\0) + e^|l)) ® |V) ® |0 . . . 0) + 
a/2 

U*WP U-=(\0) + e^|l)) <8) |V> <8> |0 — 0> 
\/2 

= U\l - P Q )U^=(\0) + e^|l» ® |V) ® |0. . . 0) + 
a/2 

[/t^p [7 J_(|o) + e^|l)) ® |V) ® |0 . . . 0) 
a/2 

= -L(|0) + e^|l))®|V)®|0...0)- 

rfP U-=(\0) + e^|l)) ® |V) ® |0. . . 0) + 
v2 

C/tPoC/^dO) +e iv |l)) ® |V)® |0...0) 
a/2 

= : |$) - {(fx) + |</? 2 ) . 

Note that the vectors \cpi) and \<p2) have at most norm <Je due to the high probability 
of acceptance. One checks easily that 

minll I*) - e i7 |^)|| = II \% - e^ltt) II = 11 - exp(i<p)| • 

We conclude 

min||Z|tf) -e i7 |*)|| > |1 - exp(fy>)| -2y/e. 



With |1 — exp(i(p)\ = \/2(l — cos ip) we conclude that the minimal norm difference 
between Z and e* 7 l is at least 



V2(l -cosv9) -2y/e. 

□ 

As mentioned in the remark after Definition |2] e can be made arbitrarily small. For 
small <p the lower and upper bounds on the norm distances between U and the trivial 
transformations are approximatively given by 

and 

y/2tp-2y/l, 

respectively. This shows that for sufficiently small e there is a sufficient separation 
between the lower and upper bound. This shows that every oracle that is able to 
decide whether Z = ulWU x V is close to a trivial transformation can be used to decide 
whether x is in L. 
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